Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\recover] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\recover] 'ImagePath' = '"%WINDIR%\SysWOW64\polstore\recover.exe"'
- 'recover' "%WINDIR%\SysWOW64\polstore\recover.exe"
- 'recover' %WINDIR%\SysWOW64\polstore\recover.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAFIAVABRAFYAZgBuAGQAPQAnAEEAQwBBAEsARAB6AG8AdAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYABDAFUAYABSAGAAaQB0AFkAYABQAFIAbwB0AG8AQwBgAE8AbAAiAC...
- %HOMEPATH%\162.exe
- %WINDIR%\syswow64\polstore\recover.exe
- %HOMEPATH%\162.exe в %WINDIR%\syswow64\polstore\recover.exe
- '95.#.180.128':80
- http://in###webr.com/morgans/dQ/
- http://95.#.180.128/ORKq0o2fabt/XwMpXfPsp/5P45k5c/p5bFthHKfKnrt25Y2tj/
- DNS ASK es###tors.com
- DNS ASK im###pros.com
- DNS ASK in###webr.com
- '%HOMEPATH%\162.exe'
- '%WINDIR%\syswow64\polstore\recover.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAFIAVABRAFYAZgBuAGQAPQAnAEEAQwBBAEsARAB6AG8AdAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYABDAFUAYABSAGAAaQB0AFkAYABQAFIAbwB0AG8AQwBgAE8AbAAiAC...' (со скрытым окном)